A new OWASP managed-rule pack is about to go live on the lock-booking site’s WAF. How should the security engineer introduce the policy mode?
Select an answer to reveal the explanation.
Short Explanation
New managed rules? Start in Detection so you can see the false alarms, tune exclusions, then flip to Prevention. Going Prevention cold on day one is how you lock out real users.
Full Explanation
WAF policy modes include Detection (log only) and Prevention (block). Introducing a new OWASP managed-rule pack in Detection first allows tuning false positives before enforcing Prevention. Enabling Prevention immediately without observation increases outage risk. Azure Firewall threat intelligence is a different product control. Defender for Cloud Secure Score is Domain 4 posture and does not set WAF Detection versus Prevention.